Answered: [Security threat] tags are not sanitized in extra question field

Post date: 2020-07-01 00:44:51
Views: 187

Hey q2apro, I think you are testing the default q_view_extra($q_view); function.

The default function is still safe. But if you pull the content from the databse, it's not safe.

First, look! The script is stored in database.

database

Second, if create a function to pull that content form the datase:

public function q_item_extra($q_item)
{
$postidz = $q_item'raw']'postid'];
$extra = qa_db_read_one_value(qa_db_query_sub(
       'SELECT content FROM ^postmetas WHERE title="qa_q_extra" AND postid=#',
        $postidz
   ), true);
 
 //$extra = $q_item'extra']'content'];
 
        $this->output('My info:'.$extra);   
   
}

Here's the result:

test

I hope you'll get my point.

Please click Here to read the full story.
 
Other Top and Latest Questions:
Be careful buying the top 10 ETFs of 2025: They have 'very little, if any' role in your portfolio, says expert
Tesla reports 418,227 deliveries for the fourth quarter, down 16%
Watch Trump's full comments following the U.S. strike against Venezuela
Estate planning helps 'forestall bad outcomes,' author says — you need some key documents even at age 18
Lucid increases EV deliveries by 55% in 2025, meets lowered guidance
Who controls Venezuela's oil now? What Maduro's arrest means for energy markets
Protest over AI, climate crisis leaves tens of thousands without power in Berlin
Ousted Venezuelan leader Maduro gets Julian Assange's lawyer to represent him in drug case
Chick-fil-A launches its biggest ever marketing campaign as restaurant industry traffic shrinks
Comcast spinoff Versant starts trading on Nasdaq in rare media debut